
CVE-2015-6967
Python exploit for CVE-2015-6967 targeting Nibbleblog with a reverse shell payload. Executes authenticated remote code execution via file upload…

Python exploit for CVE-2015-6967 targeting Nibbleblog with a reverse shell payload. Executes authenticated remote code execution via file upload…

This is an exploit for CVE-2024-23346 that acts as a "terminal" (tested on chemistry.htb)

Proof-of-concept exploit for CVE-2022-28117 enabling arbitrary file read via file:/// URI scheme in Navigate CMS, with authentication support.

Exploit for CVE-2024-22274 that creates a privileged user and spawns a root SSH shell on a target host using provided credentials.

Atlassian Confluence Server and Data Center: CVE-2022-26138

CVE-2007-2447 samba remote code execution

OpenSSH 2.3 up to 7.4 Mass Username Enumeration (CVE-2018-15473).

OpenSSH 2.3 < 7.7 - Username Enumeration


OpenSSH Username Enumeration - CVE-2016-6210

Unauthenticated Xerte Online Toolkits exploit. Requires knowing a valid username.

Exploits unauthenticated privilege escalation in SMS Alert WooCommerce plugin (CVE-2026-11387) via OTP bypass and arbitrary password reset, with…

DVR username password recovery.

A vulnerability, which was classified as critical, was found in SourceCodester Food Ordering Management System 1.0. Affected is an unknown function…

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

Remote Command Injection Vulnerability (CVE-2007-2447), allows remote attackers to execute arbitrary commands by specifying a Samba username…

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username

just remeber how small mistake in santisize username could give yoy root access to the full machine